Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43999
Total
3569
Critical
13202
High
13005
Medium
CVE ID Severity Score Description Published
CVE-2026-79672 MEDIUM 5.5 Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation … Aug 25, 2026
CVE-2026-79671 MEDIUM 5.5 Ech0 through 4.2.1 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to … Aug 25, 2026
CVE-2026-79670 MEDIUM 4.8 Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint that validates Content-Type using only client-supplied headers without server-side inspection. Attackers … Aug 25, 2026
CVE-2026-79669 MEDIUM 4.3 Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read and stream all server logs. Attackers can access … Aug 25, 2026
CVE-2026-79668 MEDIUM 5.3 Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endpoint that allows unauthenticated attackers to increment engagement metrics without identity verification or … Aug 25, 2026
CVE-2026-79667 HIGH 7.6 Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege) restrictions on several privileged admin routes. Multiple privileged endpoints (e.g., /api/inbox, /api/panel/comments, … Aug 25, 2026
CVE-2026-79666 MEDIUM 6.5 Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing any authenticated user to access system logs. Attackers with valid user sessions … Aug 25, 2026
CVE-2026-79665 HIGH 8.8 Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope validation in RequireScopes middleware, allowing logged-in non-admin users to access admin endpoints. … Aug 25, 2026
CVE-2026-79664 HIGH 7.4 Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent … Aug 25, 2026
CVE-2026-79663 MEDIUM 4.8 Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where tag names and markdown content are rendered without HTML escaping. … Aug 25, 2026
CVE-2026-79662 HIGH 8.0 Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClientRedirect (internal/service/auth/auth.go) that compares only the scheme and host of the client-supplied redirect_uri against … Aug 25, 2026
CVE-2026-79661 MEDIUM 6.5 Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without authentication or rate limiting. Unauthenticated attackers can increment the fav_count counter … Aug 25, 2026
CVE-2026-79660 MEDIUM 5.3 Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON serialization tags on the Comment model. Unauthenticated attackers … Aug 25, 2026
CVE-2026-79659 HIGH 7.7 Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL … Aug 25, 2026
CVE-2026-79658 HIGH 7.5 Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP … Aug 25, 2026
CVE-2026-79657 CRITICAL 9.8 NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers … Aug 25, 2026
CVE-2026-78864 MEDIUM 6.3 A vulnerability was determined in liketrek TREK up to 3.0.22. The affected element is the function journeyService.updateEntry of the file server/src/nest/journey/journey.controller.t of the component Journey … Aug 25, 2026
CVE-2026-78684 MEDIUM 5.3 vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream … Aug 25, 2026
CVE-2026-77997 UNKNOWN Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to … Aug 25, 2026
CVE-2026-77996 UNKNOWN Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a … Aug 25, 2026
CVE-2026-77824 MEDIUM 4.9 The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' parameter in all versions up to, … Aug 25, 2026
CVE-2026-75971 HIGH 7.2 The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … Aug 25, 2026
CVE-2026-75908 MEDIUM 4.3 The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not … Aug 25, 2026
CVE-2026-57910 UNKNOWN Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges. Aug 25, 2026
CVE-2026-57909 UNKNOWN A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system. Aug 25, 2026